Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/shennawardana23/skillme/diff-analysisnpx skills add shennawardana23/skillme --skill diff-analysisgit clone --depth 1 https://github.com/shennawardana23/skillmeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/shennawardana23/skillme/diff-analysis)<a href="https://agentmods.dev/skills/shennawardana23/skillme/diff-analysis"><img src="https://agentmods.dev/badge/skills/shennawardana23/skillme/diff-analysis.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00084 | $0.01157 |
| Opus 5 | $0.00042 | $0.00579 |
| Sonnet 5 | $0.00017 | $0.00231 |
| Haiku 4.5 | $0.00008 | $0.00116 |
Grade A, and why
diff-analysis scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 79 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Diff Analysis
A diff-shaped review: it only looks at what changed, not the whole file, and produces one risk verdict. Run all three tracks over the same diff, then synthesize — don't review them one after another as separate passes, since a single line often matters to more than one track (a deleted nil-check is both a Track A complexity signal and a Track C security signal).
Track A: complexity
For each changed file:
- Cyclomatic complexity change — did the diff add nested conditionals, new loops, new goroutines?
- Function length — is any new or modified function longer than ~40 lines?
- Removed safety guards — were any validation checks, nil-checks, or early-returns deleted?
- New external dependencies — does the diff add new imports? Are they necessary, or does an existing dependency already cover this?
Track B: style and convention
- Naming — do new identifiers follow the language's naming convention?
- Error handling — are new errors returned/wrapped properly? Any new
_ =suppressions? - Documentation — are new exported symbols documented?
- Test additions — does the diff include tests for the new behavior?
- Dead code — does the diff add unreachable code or unused variables?
Track C: security impact
- Removed auth checks — did the diff delete or comment out authentication/authorization code?
- New SQL/command strings — does the diff introduce a new string-built query or shell command?
- Weakened validation — did any input validation become less strict (a
mustcheck turned into a warning, a bound loosened)? - New exposed endpoints — are new routes/handlers added without the same security middleware as their neighbors?
- Dependency updates — if a lockfile/
go.modchanged, are the new or updated dependencies from a trusted source with no known critical CVEs?
Synthesis
## Risk Level: LOW | MEDIUM | HIGH | CRITICAL
### Risk justification
<One paragraph explaining the overall rating, referencing which track(s) drove it>
## Key Changes
- <What the diff actually does, in plain language>
## Required Actions (must complete before merge)
1. <Specific action with file:line reference>
## Recommended Improvements (should do)
1. ...
## Nice-to-have
1. ...
## Merge verdict: APPROVE | REQUEST_CHANGES | BLOCK
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 79 lines · 84 tokens per session scan A 4e6bc5622e5f
diff-analysis is a skill published in the GitHub repository shennawardana23/skillme (2 stars, last pushed 8d ago), licensed Apache-2.0. It adds 84 tokens to every session and 1,157 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
writing-skills
Use when creating new skills, editing existing skills, or verifying skills work before deployment.
receiving-code-review
Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation.
writing-plans
Use when you have a spec or requirements for a multi-step task, before touching code.
skill-creator
Create, improve, evaluate, benchmark skills. Use when authoring a new skill, updating an existing one, running evals, or optimizing a skill's description for triggering. Don't use for invoking skills, writing prose, or scaffolding Python projects.
skill-index-updater
Add GitHub skill repos to the ASM index: clone, audit, eval, regenerate index, rebuild catalog, open PR. Use when given GitHub URLs to onboard. Don't use for authoring (skill-creator), improving (skill-auto-improver), or install (asm install).
hello-world
A minimal test skill that greets the user and demonstrates the ASM publish workflow.